TLDR
Several DeFi bridges and cross-chain protocols were hacked within hours, with attackers stealing more than $35 million in crypto from AFX Trade, Verus, and B Network.
- AFXs Arbitrum bridge, Veruss Ethereum bridge, and B Networks staking system were exploited using compromised keys and flawed upgrade or validation logic, not broken cryptography.
- The incidents highlight that most major DeFi losses now come from operational security weaknesses around keys and governance, even on audited or established protocols.
- Crypto users should watch how these teams handle compensation, key rotation, and architecture changes, and treat cross-chain bridges as high-risk infrastructure for the foreseeable future.
Deep Dive
1. What Was Attacked And How
In a roughly six hour window, at least three bridges and cross-chain protocols were drained for over $35 million, according to multiple reports on Bitcoin and Ethereum-linked systems. AFX Trade, a perpetuals protocol on Arbitrum, lost about $24.15 million in USDC after an attacker gained control of validator signing keys for its third-party bridge, meeting the quorum needed to authorize withdrawals without changing the contract code.
Around the same time, the Verus Ethereum Bridge was hit again, losing about $7.54 million in ETH, tokenized BTC, stablecoins and other tokens via its import path, using the same bridge contract and bug class as a May exploit that had already drained millions. B Network, a Bitcoin scaling protocol, reportedly lost roughly $3.86 million when an attacker seized upgrade authority over its staking contract, using privileged controls to drain funds. Together, these events match the reported total of about $35 to $35.5 million in losses from bridges and cross-chain infrastructure.
2. Why This Matters For DeFi
A common theme in these hacks is that cryptography held, but trust controls did not. In AFXs case, the bridge logic worked as designed once compromised keys signed the withdrawal. In Verus and B Network, import paths and upgrade powers allowed attackers to trigger or authorize payouts that should never have been possible under robust governance.
This pattern fits broader data showing that most recent DeFi losses come from compromised keys, validators, backend systems and admin controls rather than pure smart contract bugs, as highlighted in a Q2 2026 security report that found nearly nine out of ten dollars stolen were tied to operational security failures. Audits alone did not prevent these breaches when critical controls sat outside the reviewed contracts.
For users and institutions, the real risk lens is how keys, signers and upgrade powers are managed, not just whether a protocol has an audit or attractive yields.
3. What To Watch Next
Immediate questions are whether affected teams will compensate users, rotate and harden keys, or fundamentally redesign their bridges. B Network has already signaled intent to compensate affected stakers, and Arbitrums core team stressed that its native bridge was not impacted, underlining the distinction between ecosystem infrastructure and individual protocol bridges.
More broadly, this cluster of exploits adds to pressure for stricter operational standards around timelocks, multisig setups, withdrawal whitelists, and continuous monitoring, especially on Arbitrum and other chains that have seen repeated large hacks. For active DeFi users, practical monitoring means tracking which bridges they rely on, how much value is custodied there, and whether those systems have transparent, multi-party control rather than single points of failure.
Conclusion
The loss of more than $35 million across AFX, Verus, and B Network is another reminder that cross-chain bridges are among the weakest links in DeFi, not because the math is broken but because human-controlled keys and governance can fail. Until bridge designs shift toward stricter, verifiable controls and away from concentrated authority, treating these systems as high-risk intermediaries - and sizing exposure accordingly - is likely to remain the safest stance.
